forked from glzjin/CTFd-Whale
-
Notifications
You must be signed in to change notification settings - Fork 29
/
api.py
138 lines (119 loc) · 4.97 KB
/
api.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
from datetime import datetime
from flask import request
from flask_restx import Namespace, Resource, abort
from CTFd.utils import get_config
from CTFd.utils import user as current_user
from CTFd.utils.decorators import admins_only, authed_only
from .decorators import challenge_visible, frequency_limited
from .utils.control import ControlUtil
from .utils.db import DBContainer
from .utils.routers import Router
admin_namespace = Namespace("ctfd-whale-admin")
user_namespace = Namespace("ctfd-whale-user")
@admin_namespace.errorhandler
@user_namespace.errorhandler
def handle_default(err):
return {
'success': False,
'message': 'Unexpected things happened'
}, 500
@admin_namespace.route('/container')
class AdminContainers(Resource):
@staticmethod
@admins_only
def get():
page = abs(request.args.get("page", 1, type=int))
results_per_page = abs(request.args.get("per_page", 20, type=int))
page_start = results_per_page * (page - 1)
page_end = results_per_page * (page - 1) + results_per_page
count = DBContainer.get_all_alive_container_count()
containers = DBContainer.get_all_alive_container_page(
page_start, page_end)
return {'success': True, 'data': {
'containers': containers,
'total': count,
'pages': int(count / results_per_page) + (count % results_per_page > 0),
'page_start': page_start,
}}
@staticmethod
@admins_only
def patch():
user_id = request.args.get('user_id', -1)
result, message = ControlUtil.try_renew_container(user_id=int(user_id))
if not result:
abort(403, message, success=False)
return {'success': True, 'message': message}
@staticmethod
@admins_only
def delete():
user_id = request.args.get('user_id')
result, message = ControlUtil.try_remove_container(user_id)
return {'success': result, 'message': message}
@user_namespace.route("/container")
class UserContainers(Resource):
@staticmethod
@authed_only
@challenge_visible
def get():
user_id = current_user.get_current_user().id
challenge_id = request.args.get('challenge_id')
container = DBContainer.get_current_containers(user_id=user_id)
if not container:
return {'success': True, 'data': {}}
timeout = int(get_config("whale:docker_timeout", "3600"))
c = container.challenge # build a url for quick jump. todo: escape dash in categories and names.
link = f'<a target="_blank" href="/challenges#{c.category}-{c.name}-{c.id}">{c.name}</a>'
if int(container.challenge_id) != int(challenge_id):
return abort(403, f'Container already started but not from this challenge ({link})', success=False)
return {
'success': True,
'data': {
'lan_domain': str(user_id) + "-" + container.uuid,
'user_access': Router.access(container),
'remaining_time': timeout - (datetime.now() - container.start_time).seconds,
}
}
@staticmethod
@authed_only
@challenge_visible
@frequency_limited
def post():
user_id = current_user.get_current_user().id
ControlUtil.try_remove_container(user_id)
current_count = DBContainer.get_all_alive_container_count()
if int(get_config("whale:docker_max_container_count")) <= int(current_count):
abort(403, 'Max container count exceed.', success=False)
challenge_id = request.args.get('challenge_id')
result, message = ControlUtil.try_add_container(
user_id=user_id,
challenge_id=challenge_id
)
if not result:
abort(403, message, success=False)
return {'success': True, 'message': message}
@staticmethod
@authed_only
@challenge_visible
@frequency_limited
def patch():
user_id = current_user.get_current_user().id
challenge_id = request.args.get('challenge_id')
docker_max_renew_count = int(get_config("whale:docker_max_renew_count", 5))
container = DBContainer.get_current_containers(user_id)
if container is None:
abort(403, 'Instance not found.', success=False)
if int(container.challenge_id) != int(challenge_id):
abort(403, f'Container started but not from this challenge({container.challenge.name})', success=False)
if container.renew_count >= docker_max_renew_count:
abort(403, 'Max renewal count exceed.', success=False)
result, message = ControlUtil.try_renew_container(user_id=user_id)
return {'success': result, 'message': message}
@staticmethod
@authed_only
@frequency_limited
def delete():
user_id = current_user.get_current_user().id
result, message = ControlUtil.try_remove_container(user_id)
if not result:
abort(403, message, success=False)
return {'success': True, 'message': message}